goldfinger777
Experienced member
- Messages
- 1,020
- Likes
- 5
I have been trying to track down a friendly IT person to go through the security bits on the VPS with me.
I do have the auto login setup with a separate non admin account if that makes a difference. Just allowed full access to the single custom directory where MT4 is installed.
I would have thought that without physical access to the VPS machine it would be difficult to read the password out of the registry? If it is that is accessible then surely a hacker could just edit the registry and kill the server even if the password was not in plain text.
£15 sounds reasonable if it is more secure. I set things up in a bit of a hurry before having to "go live" and go on holiday.
Thanks for the advice; it is definitely something to look into.
There are a number of ways that an attacker could access your registry if he really wanted to. However it's more likely to happen when you unwittingly install a piece of software on your machine that is not what it seems (for example a bit of malware). All programs that get installed on a PC have access to the registry, so it is at this point that an attacker could retrieve your password if it's stored in plain text in the registry.